Security & Trust

Bank-hosted by design.

Architecture principles

Bank-local data plane

Customer IDs, balances, rates, transactions, counterparties, decisions, and outcomes are designed to remain inside the institution-controlled environment.

Read-only pilot posture

The pilot does not require core write-back, autonomous pricing, money movement, or autonomous customer communication.

Deterministic decisions

Material risk and economic calculations are rule-based, versioned, and designed to be reproducible from bank-approved facts and configuration.

Hard-data standard

Runoff decisions use auditable inputs such as balances, transaction movement, rates, CD maturity, uninsured exposure, loans, treasury activity, and funding assumptions.

Data minimization

KeptCap does not require card PAN, CVV, online-banking passwords, customer passwords, or Social Security numbers for the commercial-deposit decision workflow. Early pilots can use masked or pseudonymous identifiers where appropriate.

Current pilot controls

ControlStatusCurrent approach
Bank-hosted application and databaseImplementedContainerized application with bank-local PostgreSQL reference runtime.
Outbound mode disabled by defaultImplementedThe reference pilot does not require customer-data egress.
Validated data ingestionImplementedRequired-field, type, institution, checksum, and duplicate-import controls.
Audit historyImplementedImports, decisions, configuration changes, actions, and outcomes are recorded locally.
Configuration versioningImplementedBank policy inputs are validated, versioned, and tied to decision evidence.
SSO / bank identityInstitution-specificProduction direction is SAML or OIDC with bank-managed identity and MFA.
KMS, SIEM, backups, image scanningInstitution-specificMapped to the bank's approved cloud and security standards during deployment.

AI boundary

AI is not required for the pilot decision engine. If a narrative layer is added later, it should remain evidence-bound and should not perform the financial math or alter the underlying deterministic recommendation.

Assurance posture

KeptCap does not currently represent that it has completed SOC 2 or ISO 27001 certification. Those programs, penetration testing, formal vulnerability management, incident response, business continuity, and related production controls are part of the production-readiness roadmap and buyer requirements.

Public demo boundary

app.keptcap.com is a synthetic product demonstration. No real bank customer data should be submitted there. Institution pilots use the separate bank-hosted runtime and institution-specific security controls.

Security and vendor-risk inquiries

For architecture, vendor-risk, security questionnaire, or pilot-security discussions, contact hello@keptcap.com.